Stars
Aya is an eBPF library for the Rust programming language, built with a focus on developer experience and operability.
Dynamically resolve API function addresses at runtime in a secure manner.
Rusty DoublePulsar - Cobalt Strike User-Defined Reflective Loader (UDRL) in Rust (Codename: DoublePulsar)
A desktop operator console for Sliver C2, built with Wails. Provides a native, lightweight GUI interface for Sliver by directly interfacing with its gRPC service no proxies or protocol reimplementa…
IP addresses break, dial keys instead. A library that adds QUIC + NAT Traversal to your apps.
RoguePlanet Windows Defender Vulnerability
Rust's extended standard library: simplicity, performance and supply chain security for everyone.
Radio frequency scanner with recon and offensive capabilities
Open-source cross-platform endpoint detection engine for Windows, macOS, and Linux using ETW, ESF, eBPF, Sigma, YARA, IOCs, and ECS NDJSON alerts.
A stealthy, fully syscalled C/C++ userland anti-debugging library for Windows, designed to protect software from reverse engineering
AIRecon is an autonomous cybersecurity agent that combines a self-hosted Large Language Model (Ollama) with a Kali Linux Docker sandbox and a Textual TUI. It is designed to automate security assess…
BYOVD research use cases featuring vulnerable driver discovery and reverse engineering methodology. (CVE-2025-52915, CVE-2025-1055, CVE-2026-3609, CVE-2026-8501).
A complete Go port of Impacket - 63 CLI tools and 24 libraries for Windows & Active Directory protocol attacks, compiled to a single dependency-free binary.
Generates x86, x64, or AMD64+x86 position-independent shellcode that loads .NET Assemblies, PE files, and other Windows payloads from memory and runs them with parameters
Mythic implant written in Rust ported from https://github.com/Nariod/linky
64-bit, position-independent implant template for Windows in Rust.
Materials for the workshop "Red Team Ops: Havoc 101"
Fritter is a heavily modified fork of TheWover and Odzhan's Donut shellcode generator.
Extract Windows credentials directly from VM memory snapshots and virtual disks
An AI-powered agentic red team framework that automates offensive security operations, from reconnaissance to exploitation to post-exploitation, with zero human intervention.
AV/EDR evasion via direct and indirect system calls Windows NT 3.1 through Windows 11 24H2 · x64 · x86 · WoW64 · ARM64
A BloodHound OpenGraph collector that models Windows local privilege escalation as interconnected attack paths.
Modern embedded framework, using Rust and async.